← Vulnerability feed

Vulnerability record · CVE-2020-13927 · published 10 November 2020

CVE-2020-13927: Apache Airflow Experimental API missing authentication by default

Apache · Airflow

Airflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated callers. Airflow 1.10.11 changed the default to deny all requests, but existing installations must explicitly set the deny_all auth backend to be protected. The flaw matters because it is a missing-authentication issue on a critical function in a widely deployed orchestration platform.

9.8 CVSS 3.1 Critical CISA KEV since 18 Jan 2022 EPSS 100% · top 0.1% CWE-306 · Missing authentication for critical functionCWE-1188 · Insecure default initialization
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed, near-maximum EPSS, and public exploit code make this an urgent unauthenticated remote compromise risk.

What it is

Airflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated callers. Airflow 1.10.11 changed the default to deny all requests, but existing installations must explicitly set the deny_all auth backend to be protected. The flaw matters because it is a missing-authentication issue on a critical function in a widely deployed orchestration platform.

Impact

An unauthenticated attacker gains full access to the Experimental API, which can lead to remote code execution and complete compromise of the Airflow instance and its managed workflows.

Attack surface

Reachable over the network via the Airflow Experimental API endpoint; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Listed in CISA KEV since 2022-01-18 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.99778 (percentile 0.99955); public exploit references exist on Packet Storm.

What to do

  • Upgrade to Airflow 1.10.11 or later, which denies Experimental API requests by default.
  • On existing installs, set [api]auth_backend = airflow.api.auth.backend.deny_all in airflow.cfg per the Updating Guide.
  • If the Experimental API is not needed, disable it entirely.
  • Restrict network access to the Airflow web/API port to trusted hosts only.
  • Review Airflow configuration for any other unauthenticated endpoints or insecure defaults.

Detection

  • Monitor Airflow API access logs for requests to Experimental API endpoints from unexpected or unauthenticated sources.
  • Alert on configuration changes to [api]auth_backend or other Airflow security settings.
  • Hunt for signs of unauthorized DAG creation or modification, which may indicate API abuse.
  • Check for outbound connections or process execution on Airflow hosts consistent with post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-13927 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Apache Airflow's Experimental API Authentication Bypass". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13927 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-11978Apache Airflow example DAG command injectionApache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands a…KEVEPSS 99%analysed9.8CVE-2026-33264Apache airflow deserialization of untrusted data vulnerabilityA bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …EPSS 1.6%9.8CVE-2023-25754Apache airflow vulnerabilityPrivilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.EPSS 2.3%9.8CVE-2023-22884Apache airflow command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…EPSS 11%9.8CVE-2022-40189Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…EPSS 4.1%9.8CVE-2022-38649Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…EPSS 3.3%9.8CVE-2022-38054Apache airflow vulnerabilityIn Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.EPSS 2.1%9.8CVE-2021-38540Apache Airflow variable import endpoint missing authenticationThe variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add o…EPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13927), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.